-
v0.1.47 Stable
released this
2026-07-21 18:12:32 +00:00 | 50 commits to main since this release- Registry pull secret flips to the bare
registrystore.config/seanfarm/registry-pull-secret.yamlrepoints its
secretStoreRef fromzot-alice-registry-credentials→zot-registry-registry-credentialsahead of the XRegistry/alice
teardown (pull is anonymous; repointed so the ExternalSecret stays healthy after alice is gone). - Deploys are GATED on release-green (universal, structural). The rendered
<project>-deploysensors
(argocd/flux/ibmi taxonomies) now trigger on a newpipeline-releaseresource EventSource when the
project'sPipelineReleasereachesstatus.deployable==true— instead of on a gitmain-push. Because
deployablelatches true only when the WorkflowProjector observes the release-execution Workflow reach
Succeeded(tag+sign+promote+ff-of-main done), a deploy can no longer start before its release is green
(the prior main-push trigger raced ahead — main advances mid-release). The deploy consumes the release
CR'sspec.sha(the actually-shipped commit), and a deterministic<project>-deploy-<sha12>Workflow
name dedups the EventSource's repeat status-update fires. NewsensorSpecfields
(EventSourceName/EventName/FilterFields/DeterministicName) default to the forgejo webhook so every
build/staging/autoland sensor renders byte-identically. Thepipeline-releaseEventSource + its RBAC ship
in sean/pipelinesbundle/workflows-infra-bare.
Included changes (v0.1.46 -> v0.1.47)
421abb0ff0b2feat(deploy-gate): render -deploy sensors on release-deployable, not main-push1111113687f4chore(registry): flip pull-secret store to zot-registry-registry-credentials
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Registry pull secret flips to the bare